Law / United Arab Emirates

United Arab Emirates

privacy

The UAE runs three legally distinct data-protection regimes that must not be collapsed into one posture: the federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, PDPL, in force since 2022-01-02, onshore UAE), the DIFC Data Protection Law No. 5 of 2020 (in force since 2020-07-01, Dubai International Financial Centre free zone only, enforced by the DIFC Commissioner of Data Protection), and the ADGM Data Protection Regulations 2021 (Abu Dhabi Global Market free zone only, enforced by its own Commissioner of Data Protection under ADGM's separate court system).

All three were read at primary source. All three fold biometric data into a General Data Protection Regulation (GDPR)-style sensitive or special category with materially identical definitions naming facial images as a worked example, so a voiceprint or faceprint requires an elevated legal basis, ordinarily explicit consent, in each regime.

The federal PDPL's Article 28 requires Cabinet-issued Executive Regulations to complete its operative detail, including the Article 9 breach-notification timeline; that Executive Regulation's existence and text could not be confirmed at primary source in this research.

The corpus's own candidate citing "Cabinet Resolution No. 83 of 2022" as the PDPL Executive Regulations is verified wrong: that instrument number is in fact the Technical Regulations for Vehicle Speed Measuring Devices (Radar), an unrelated traffic-enforcement rule, and is not authored here as an instrument.

Secondary compliance trackers point to Cabinet Decision No. 33 of 2024 as the actual Executive Regulation, but its own primary-source page could not be located and confirmed, so this document treats the federal PDPL's Executive Regulations as unconfirmed pending a further pass, and records the Decree-Law's own substantive provisions as in force on their own terms.

14 instruments named 7 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Breach notification

ADGM Data Protection Regulations, breach notification

cite ADGM Data Protection Regulations 2021, personal data breach notification provisions stage IN FORCE in force since 2021-02-14 binds private bodies source official consolidated Regulations text (PDF), ADGM rulebook
What it requires

The ADGM Data Protection Regulations set an explicit 72-hour breach-notification rule to the Commissioner of Data Protection, language read verbatim and drawn from the same family as General Data Protection Regulation (GDPR) Art. 33, unless the breach is unlikely to pose a risk to individuals' rights.

This is the only one of the UAE's three regimes where a specific notification window was confirmed by direct reading in this research pass; the federal PDPL defers its timeline to unconfirmed Executive Regulations, and the DIFC Law's own breach-notification timeline (Part 7) was not individually pulled.

Federal Decree-Law on the Protection of Personal Data, breach notification

cite Federal Decree-Law No. 45 of 2021, Art. 9 stage IN FORCE in force since 2022-01-02 binds public and private bodies source official statute text, UAE Legislation portal
What it requires

Art. 9 requires the Controller to notify the Bureau of a breach that would prejudice the privacy, confidentiality, or security of personal data, at the time it becomes aware of the breach, within a period the Decree-Law itself defers to the Executive Regulations. No fixed number of hours or days is stated in the Decree-Law's own text; the timeline is not established pending the unconfirmed Executive Regulations (see the jurisdiction summary).

Data Subject notification is also required where the breach meets a threshold the Decree-Law's text does not fully set out in the provisions read.

Comprehensive regime

ADGM Data Protection Regulations, comprehensive regime

cite ADGM Data Protection Regulations 2021 (consolidated February 2024) stage IN FORCE in force since 2021-02-14 binds private bodies source official consolidated Regulations text (PDF), ADGM rulebook
What it requires

The ADGM Data Protection Regulations are the equivalent statute of the Abu Dhabi Global Market free zone (Abu Dhabi's Al Maryah and Al Reem Island financial free zone), enforced by ADGM's own Commissioner of Data Protection under ADGM's separate court system, and apply only within that free-zone footprint, not to a UAE business operating outside it.

This document cites the consolidated text as amended through February 2024; the exact original 2021 commencement date was not independently re-derived from primary text in this research pass, so 2021-02-14 is carried from the corpus's own record rather than independently confirmed. Section 1's Biometric Data definition names facial images and dactyloscopic data as worked examples, with the same adequacy-plus-alternative-safeguards cross-border transfer structure as the federal PDPL and DIFC Law. No source-based exclusion for a recording-derived biometric identifier was found.

DIFC Data Protection Law, comprehensive regime

cite DIFC Law No. 5 of 2020 stage IN FORCE in force since 2020-07-01 binds private bodies source official consolidated statute text, published at assets.u.ae
What it requires

The DIFC Data Protection Law is a separate statute of the Dubai International Financial Centre free zone, in force since 2020-07-01, enforced by the DIFC Commissioner of Data Protection, not the federal Bureau. It applies only within the DIFC's own geographic free-zone footprint (Dubai's financial district), not to a UAE business operating onshore elsewhere. Controller and Processor are General Data Protection Regulation (GDPR)-style defined roles (Sched. 1). Sched.

1's Special Categories of Personal Data includes "genetic data and biometric data where it is used for the purpose of uniquely identifying a natural person," with no source-based exclusion for an identifier derived from a recording, so processing such data ordinarily requires explicit consent or another qualifying condition.

The DIFC framework is close to full GDPR Chapter III parity on data-subject rights (portability at Art. 37, automated decision-making and profiling safeguards at Art. 38, non-discrimination at Art. 39, confirmed by the Law's own index), and Arts. 26-27 set a near-identical adequacy-plus-alternative-safeguards structure to the federal PDPL for cross-border transfer.

The individual operative texts of these articles, and of the Part 7 breach-notification provisions and any private-right-of-action provision, were not each pulled verbatim in this research pass; this document records the structure the index confirms rather than asserting undconfirmed detail.

Federal Decree-Law on the Protection of Personal Data, comprehensive regime and lawful basis

cite Federal Decree-Law No. 45 of 2021, Arts. 1, 4 stage IN FORCE in force since 2022-01-02 binds public and private bodies source official statute text, UAE Legislation portal
What it requires

The federal PDPL is the UAE's onshore comprehensive personal-data statute, applying outside the DIFC and ADGM free zones. Processing requires a lawful basis, most commonly the Data Subject's consent, with Art. 4 listing alternative grounds including a consent exception at Art. 4(2) for data the Data Subject has made public by their own act. Controller and Processor are General Data Protection Regulation (GDPR)-style defined roles, with the Controller determining purposes and means and bearing primary compliance duty.

Art. 1's Biometric Data definition names facial images and fingerprints as worked examples and lists Biometric Data as a category of Sensitive Personal Data, so an identity-linked voiceprint or faceprint ordinarily requires the Data Subject's explicit consent as its legal basis; no exclusion for an identifier derived from a photo, video, or audio recording was found.

The Decree-Law's Art. 28 Executive Regulations, which would supply operative detail including the breach-notification timeline, could not be confirmed to exist at primary source in this research pass; a corpus candidate citing "Cabinet Resolution No. 83 of 2022" as that Executive Regulation is confirmed wrong (that instrument is an unrelated vehicle speed-radar regulation), and is not authored here.

Cross border transfer

Federal Decree-Law on the Protection of Personal Data, cross-border transfer

cite Federal Decree-Law No. 45 of 2021, Arts. 22-23 stage IN FORCE in force since 2022-01-02 binds public and private bodies source official statute text, UAE Legislation portal
What it requires

Art. 22 permits transfer of personal data outside the UAE to a jurisdiction the Bureau (the UAE Data Office) has approved as having an adequate data-protection law and enforcement authority. Where no such adequacy finding exists, Art. 23 permits transfer under a contract binding the foreign recipient to PDPL-equivalent standards, or with the Data Subject's explicit consent provided the transfer does not contradict UAE public or security interest.

No blanket data-localization requirement was found; transfer is conditioned on one of these bases rather than prohibited outright.

Enforcement supervision

Federal Decree-Law on the Protection of Personal Data, enforcement and supervision

cite Federal Decree-Law No. 45 of 2021, Arts. 25-26 stage IN FORCE in force since 2022-01-02 binds public and private bodies source official statute text, UAE Legislation portal
What it requires

The UAE Data Office ("the Bureau", established by Federal Decree-Law No. 44 of 2021) is the federal supervisory authority. A grievance against a Bureau decision goes to the Bureau itself first under Art. 25. Administrative penalty amounts are not set in the Decree-Law itself: Art. 26 requires a separate Council of Ministers decision, on the General Director's recommendation, to list violations and set administrative penalties.

No provision creating a private right of action for a Data Subject to sue a Controller directly was found in the articles read; this is recorded as not established rather than a confirmed absence, since the full Act was not read in its entirety.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.